# Using field name other than "message" in grok match

**URL:** <https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563>\
**Category:** Elasticsearch\
**Created:** [November 24, 2020, 7:18pm UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563 "2020-11-24T19:18:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Muhammad\_Faisal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muhammad_faisal/32/79213_2.png) [@Muhammad\_Faisal](https://discuss.elastic.co/u/Muhammad_Faisal)\
**Post date:** [November 24, 2020, 7:18pm UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563/1 "2020-11-24T19:18:44Z")

</div>

i have log like below, in line 2 , i have stored custom filter value in field "method"...in line 3 , i want to use "method" field and apply it another custom filter and store this result in method 2...i don't want to change "message" field ...but its not working ...does grok match only works on "message" field...how to match pattern on user defined fields without changing default "message" field.

INFO:root:Filesystem backup started at 2020-11-24 04:30:06  
INFO:root:Backup method is volume enabled  
INFO:root:Filesystem backup ended

grok{  
match =\> { "message" =\>"(?\<Start\_Time\>Filesystem backup started._)"} (line 1)  
match =\> { "message" =\> "(?Backup method is._)"} (line 2)  
_match =\> { "method" =\>"(?:\w+$)"} (line 3)  
match =\> { "message" =\>"(?\<End\_Time\>Filesystem backup started._)"}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 24, 2020, 8:18pm UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563/2 "2020-11-24T20:18:51Z")

</div>

In `grok`, `message` is the entire event that it reads, you can't change that.

Is this a multiline log entry?

---

<div class="post-metadata">

**Author:** ![Muhammad\_Faisal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muhammad_faisal/32/79213_2.png) [@Muhammad\_Faisal](https://discuss.elastic.co/u/Muhammad_Faisal)\
**Post date:** [November 25, 2020, 4:24am UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563/3 "2020-11-25T04:24:09Z")

</div>

I need to change grok and then use a user defined variable in place of message ...if I use message it reads event but if message is replaced let's say with a field method, grpk wont read anything

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 25, 2020, 5:05am UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563/4 "2020-11-25T05:05:18Z")

</div>

If this is your message;

```auto
INFO:root:Filesystem backup started at 2020-11-24 04:30:06
INFO:root:Backup method is volume enabled
INFO:root:Filesystem backup ended

```

Then you might want something like this;

```auto
grok {
  match => {
    "message" => "%{LOGLEVEL:level}:%{USERNAME:user}:%{GREEDYDATA:log}"
  }
}

```

That will capture the relevant sections of your entire log line. Once that is extracted then you can run another grok on the `log` field that is extracted and figure out what `method` was used.

What you have won't work because you haven't extracted anything into the `method` field for grok to match.

---

<div class="post-metadata">

**Author:** ![Muhammad\_Faisal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muhammad_faisal/32/79213_2.png) [@Muhammad\_Faisal](https://discuss.elastic.co/u/Muhammad_Faisal)\
**Post date:** [November 25, 2020, 8:15am UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563/5 "2020-11-25T08:15:47Z")

</div>

sorry , i was not able to explain what i am trying to ask or achieve.

my question was this , if we match a line like below in grok using custom pattern and store it in lets say, "Start\_Time"  
grok{  
match =\> { "message" =\>"(?\<Start\_Time\>Filesystem backup started._)"}  
Next , is it possible/allowed to use , this "Start\_Time" field ,in place of "message" to match another regex and then store this result in "Variable"2  
match =\> { "Start\_Time" =\>"(?myregex._)"}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 25, 2020, 10:03am UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563/6 "2020-11-25T10:03:40Z")

</div>

Yes, that's exactly what I was saying 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2020, 10:03am UTC](https://discuss.elastic.co/t/using-field-name-other-than-message-in-grok-match/256563/7 "2020-12-23T10:03:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
